22.03.2013 Views

The Rootkit Primer - Below Gotham Labs

The Rootkit Primer - Below Gotham Labs

The Rootkit Primer - Below Gotham Labs

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Call Tables<br />

User-Mode Call Table Shorthand Description<br />

Import Address Table IAT Specifies DLL imports<br />

Kernel-Mode Call Tables (MSFT) Shorthand Description<br />

System Service Descriptor Table SSDT Stores system call addresses<br />

IRP Dispatch Table Driver-specific, routes IRPs<br />

Kernel-Mode Call Tables (Intel) Shorthand Description<br />

Global Descriptor Table GDT System-wide, install call gates<br />

Local Descriptor Table LDT Task-Specific, install call gates<br />

Interrupt Descriptor Table IDT Stores interrupt handlers<br />

Machine Specific Registers MSRs Used by SYSENTER<br />

© <strong>Below</strong> <strong>Gotham</strong> <strong>Labs</strong>, 2009<br />

14

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!